logo

punching messages in the q

ID: 6bf74b60-f6af-560b-90f4-a4ddf3bb5337

STIX ID: report--6bf74b60-f6af-560b-90f4-a4ddf3bb5337

Feed Name: SensePost Blog

Date Published: 2018-06-08

Date Updated: 2026-04-29

...
...

This research-focused post examines the security risks of IBM MQ deployments, demonstrating techniques to enumerate channels and credentials, read and inject messages, and achieve command execution via MQ services using the punch-q tool. It emphasizes how misconfigurations and weak authentication expose business processes to abuse, and offers defensive guidance including log monitoring, detection of brute-force attempts, visibility into connected clients, and an osquery extension for tracking MQ client activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.